1 00:00:00,390 --> 00:00:07,230 You can create and link GPO was to site domain or you as I said when you apply multiple GPO was to the 2 00:00:07,230 --> 00:00:08,410 same container. 3 00:00:08,490 --> 00:00:16,050 This aggregates the sets in the GPO for most policy settings the GPO with the highest precedence and 4 00:00:16,260 --> 00:00:22,790 that contains the specific set and determines the Syrians final value for a few settings. 5 00:00:22,830 --> 00:00:31,080 That final value is actually a combination of values across GPO G bills are processed on a client computer 6 00:00:31,080 --> 00:00:32,730 in the following order. 7 00:00:32,730 --> 00:00:35,090 This is important to remember this order. 8 00:00:35,130 --> 00:00:43,350 First it is applied locally so local GPO is the first one on site level Jabil then domain level GPO 9 00:00:43,590 --> 00:00:51,630 and then organizational unit GPO including and in nested o use starting with 0 you farthest from the 10 00:00:51,630 --> 00:00:53,340 user or computer object. 11 00:00:53,340 --> 00:01:02,560 So once more LSD 0 you local site domain 0 you also know that here is mentioned container container. 12 00:01:02,610 --> 00:01:07,270 In this context is meant to be an aside to the man or you. 13 00:01:07,310 --> 00:01:12,760 You should remember that you cannot apply GP always to a tedious container. 14 00:01:12,900 --> 00:01:20,100 So let's move one GP rules that apply to higher level containers pass through all SOP containers in 15 00:01:20,100 --> 00:01:27,720 that part of the active directory tree for example a policies set and let you apply through a GPO linked 16 00:01:27,810 --> 00:01:32,830 to an O U also applies to any child to use below it. 17 00:01:32,820 --> 00:01:41,050 The local GPO is processed first and there or you to the computer or user belongs is processed last. 18 00:01:41,100 --> 00:01:47,930 The last GPO processed is the effective centre so the last GPO is applied. 19 00:01:47,940 --> 00:01:54,900 We also have several group policy options that alter this default inheritance behaviour. 20 00:01:54,900 --> 00:01:57,520 These options include link order. 21 00:01:57,620 --> 00:02:04,770 Use this option to sell the president's order for GP was linked to a given container the GP or link 22 00:02:04,770 --> 00:02:10,170 with a link order of one has the highest residents of that container. 23 00:02:10,410 --> 00:02:18,270 If you change the link order it doesn't have an effect unless the GP shows that link to the same location 24 00:02:18,270 --> 00:02:19,910 have conflict and settings. 25 00:02:19,910 --> 00:02:23,980 Another group policy option is enforced with this option. 26 00:02:24,000 --> 00:02:31,860 You can specify that the GPO takes precedence over any GP shows that link to child containers. 27 00:02:32,010 --> 00:02:40,950 Additionally a GPO that the Windows operating system enforces at the demand level overrides a GPO that 28 00:02:41,040 --> 00:02:43,890 it enforces at an all you level. 29 00:02:43,890 --> 00:02:49,740 So remember the main level GPO takes precedence over all you level Jabil. 30 00:02:49,740 --> 00:02:57,710 You typically enforce a GPO to ensure that computers use company wide settings and that departments 31 00:02:57,710 --> 00:03:03,660 all administrators do not override the sentence by creating other GPO. 32 00:03:03,660 --> 00:03:08,980 The next GPO group also option sorry is block inheritance. 33 00:03:09,060 --> 00:03:17,440 With this option you can prevent and or your domain from inheriting GP O's from any parent containers 34 00:03:17,580 --> 00:03:22,040 enforced GPO links will always be inherited. 35 00:03:22,050 --> 00:03:29,220 Typically you block inheritance to enable a department to manage group policies set separately from 36 00:03:29,220 --> 00:03:34,870 the rest of organisation and one more group policy option is link enabled. 37 00:03:34,950 --> 00:03:43,080 The ability to specify whether Windows operating system processes a specific GPO link was a container 38 00:03:43,080 --> 00:03:44,310 to widget links. 39 00:03:44,370 --> 00:03:49,950 When you do not enable a link the Windows operating system doesn't process the GPO. 40 00:03:49,950 --> 00:03:57,240 Typically this is done during troubleshooting when you want to disable the processing of a GPO to eliminate 41 00:03:57,480 --> 00:04:00,210 it as a source of configuration errors. 42 00:04:00,210 --> 00:04:08,060 Also please remember that the GPO inheritance is on a per set and basis rather than a per GPO basis.